---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  annotations:
    user-authz.deckhouse.io/access-level: Editor
  name: d8:user-authz:log-shipper:editor
  {{ include "helm_lib_module_labels" (list .) | nindent 2 }}
rules:
  - apiGroups:
      - deckhouse.io
    resources:
      - clusterloggingconfigs
      - clusterlogdestinations
    verbs:
      - get
      - list
      - watch
  - apiGroups:
      - deckhouse.io
    resources:
      - podloggingconfigs
    verbs:
      - get
      - list
      - watch
      - create
      - delete
      - deletecollection
      - patch
      - update
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  annotations:
    user-authz.deckhouse.io/access-level: ClusterEditor
  name: d8:user-authz:log-shipper:cluster-editor
  {{ include "helm_lib_module_labels" (list .) | nindent 2 }}
rules:
  - apiGroups:
      - deckhouse.io
    resources:
      - clusterloggingconfigs
      - clusterlogdestinations
    verbs:
      - create
      - delete
      - deletecollection
      - patch
      - update
